Trezor users are being targeted again with sophisticated phishing messages.
Hardware wallet maker Trezor said its third-party provider was breached and warned users that an email titled “Critical Security Alert: STM32 Entropy Vulnerability” was not sent by the company but was instead a phishing attempt.
The company urged users not to click any links.
Trezor Phishing Scam
In an update on X, Trezor said it had taken down the domain and was investigating how hackers accessed its legitimate domain. The phishing message in question attempted to convince users that a serious security flaw has been found in STM32 microcontrollers used in its devices. According to the fabricated warning, STM32 microcontrollers could generate recovery phrases without enough randomness, potentially putting users’ funds at risk. The email further claims that as many as 25% of devices may be affected.
The issue may not be limited to Trezor users, according to Casa CEO and co-founder Nick Neuman. He noted that reports of similar messages have surfaced among people using the BitBox device as well.
This isn’t the first time a third-party partner connected to Trezor has suffered a security breach. In August, the platform disclosed a similar security incident involving its logistics partner, ShipMonk, which compromised personal details tied to a large number of customers.
The exposed information included contact and delivery data. An earlier disclosure put the number of affected individuals at 13,689. However, Trezor later confirmed that roughly 67,000 additional US customers were impacted, which pushed the total to 80,689 people whose information was exposed.
Hardware Concerns
A separate security test also raised concerns about the TROPIC01 chip found in Trezor’s Safe 7 wallet. In June, Ledger’s Donjon researchers found that, with specialized equipment and physical access to a device, an attacker could interfere with the chip while it checks firmware.
You may also like:
The researchers used a carefully focused 1064 nm laser to trigger faults during the boot and update process. This could allow modified firmware to run. Trezor, however, said the finding does not put users’ funds at risk.
Blockchain investigator ZachXBT has been pretty blunt about hardware wallets in the past. He had earlier said that all hardware wallets are “complete garbage” and that he wouldn’t use them for important transactions or to store funds, and suggested keeping a separate iPhone just for wallet use instead.
